IS

Srivastava, Rajendra P.

Topic Weight Topic Terms
0.344 approach analysis application approaches new used paper methodology simulation traditional techniques systems process based using
0.210 model models process analysis paper management support used environment decision provides based develop use using
0.207 risk risks management associated managing financial appropriate losses expected future literature reduce loss approach alternative
0.148 services service network effects optimal online pricing strategies model provider provide externalities providing base providers
0.115 online evidence offline presence empirical large assurance likely effect seal place synchronous population sites friends
0.114 systems information management development presented function article discussed model personnel general organization described presents finally
0.100 theory theories theoretical paper new understanding work practical explain empirical contribution phenomenon literature second implications

Focal Researcher     Coauthors of Focal Researcher (1st degree)     Coauthors of Coauthors (2nd degree)

Note: click on a node to go to a researcher's profile page. Drag a node to reallocate. Number on the edge is the number of co-authorships.

Mock, Theodore J. 2 Sun, Lili 1
assurance services 1 belief function theory 1 cost-benefit analysis 1 decision theory 1
electronic commerce 1 evidential reasoning 1 information systems security 1 risk analysis 1
sensitivity analysis 1 WebTrust 1

Articles (2)

An Information Systems Security Risk Assessment Model Under the Dempster-Shafer Theory of Belief Functions. (Journal of Management Information Systems, 2006)
Authors: Abstract:
    This study develops an alternative methodology for the risk analysis of information systems security (ISS), an evidential reasoning approach under the Dempster-Shafer theory of belief functions. The approach has the following important dimensions. First, the evidential reasoning approach provides a rigorous, structured manner to incorporate relevant ISS risk factors, related countermeasures, and their interrelationships when estimating ISS risk. Second, the methodology employs the belief function definition of risk—that is, ISS risk is the plausibility of ISS failures. The proposed approach has other appealing features, such as facilitating cost-benefit analyses to help promote efficient ISS risk management. The paper elaborates the theoretical concepts and provides operational guidance for implementing the method. The method is illustrated using a hypothetical example from the perspective of management and a real-world example from the perspective of external assurance providers. Sensitivity analyses are performed to evaluate the impact of important parameters on the model's results.
Evidential Reasoning for WebTrust Assurance Services. (Journal of Management Information Systems, 1999)
Authors: Abstract:
    We study two aspects of assurance services in electronic commerce. The first deals with the type(s) of evidential networks that will allow a professional accountant to provide assurance. Here, we develop an evidential network model for "WebTrust Assurance," a service being provided by the American Institute of Certified Public Accountants (AICPA) and the Canadian Institute of Chartered Accountants (CICA). Our model augments the AICPA/CICA approach and provides goals, subgoals and evidence relevant to the overall assurance to be provided. The aggregation of evidence and the resolution of uncertainties follow the belief-function approach. Next we develop a decision-theoretic model for the assurance-planning problem. Our approach is based on estimating the expected value of providing various levels of assurance and is illustrated with several different scenarios that may be faced in practice. We also consider the role of ambiguity in decision situations such as planning WebTrust engagements and calculate bounds in expected value based on whether auditors are conservative or not in their approach to risk.